CVE 8.8 HIGH

Better Find and Replace <= 1.7.7 - Authenticated (Subscriber+) Limited Code Injection_CVE-2025-9334

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all versions up to, and including, 1.7.7. This is due to insufficient input validation and restriction on the 'rtafar_ajax' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to call arbitrary plugin functions and execute code within those functions.

AI Analysis

Limited Code Injection vulnerability due to insufficient input validation and restriction on the 'rtafar_ajax' function, allowing authenticated attackers to execute code within arbitrary plugin functions.

Basic Information

ID CVE-2025-9334
Source Wordfence
Published Nov 8, 2025 at 05:52

Affected Product

Vendor codesolz
Product Better Find and Replace – AI-Powered Suggestions
Version *
Affected Versions codesolz Better Find and Replace – AI-Powered Suggestions *

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor codesolz
Product Better Find and Replace – AI-Powered Suggestions
Version 1.7.7

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.